Talent.com
Principal, Cybersecurity Penetration Tester
Principal, Cybersecurity Penetration TesterFidelity Investments Inc. • Boston, MA, United States
No longer accepting applications
Principal, Cybersecurity Penetration Tester

Principal, Cybersecurity Penetration Tester

Fidelity Investments Inc. • Boston, MA, United States
30+ days ago
Job type
  • Full-time
Job description

Job Description :

The mission of the penetration testing team is to protect Fidelity's assets and our customers’ livelihoods from the threat of exploitation by malicious adversaries. The penetration testing team does this by proactively identifying vulnerabilities in our systems and serving as subject matter experts to enable the business units to mitigate them in a positive, collaborative, innovative manner.

Lead testing efforts on Fidelity's web and mobile applications and supporting systems.

Replicate the actual techniques and tools used by malicious attackers in an effort to model potential external threats.

Upon completion of the assessment, you will prepare reports and present the results to application owners, developers, and business unit information security teams.

Analyze test results, draw conclusions from results, and develop targeted exploit examples.

Consult with operations and software development teams to ensure potential weaknesses are addressed.

Contribute to the research or development of tools to assist in the vulnerability discovery process.

Collaborate with other teams within Enterprise Cybersecurity to improve the overall security of Fidelity's applications and infrastructure.

Stay current on security best practices and vulnerabilities.

The Expertise You Have and The Skills You Bring

Bachelors degree or equivalent experience

5+ years of IT experience

Preferred 3+ years of hands-on web application penetration testing / ethical hacking experience

Preferred : OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.

Ability to demonstrate manual testing experience including all of OWASP Top 10

Intermediate knowledge of application security mechanisms such as authentication and authorization techniques, data validation, and the proper use of encryption

Technical knowledge of, and the ability to recognize, various types of application security vulnerabilities.

Demonstrated experience with common penetration testing and vulnerability assessment tools such as nmap, Wireshark, Nessus, NeXpose, BackTrack, Metasploit, AppScan, WebInspect, Burp Suite Professional, Acunetix, Arachni, w3af, NTOSpider

Intermediate knowledge of a programming or scripting language such a C, C#, Python, Objective C, Java, Javascript, SQL,

Intermediate knowledge of Web Services technologies such as XML, JSON, SOAP, REST, and AJAX

Intermediate knowledge of web frameworks, including XML, SOAP, J2EE, JSON and AJAX

Experience with Enterprise Java or .NET web application frameworks, including Struts and Spring

Proven analytical and problem-solving skills, as well as the desire to assist others in solving issues

Excellent interpersonal skills with a strong interest in the application security domain

Excellent communication and presentation skills and a proven ability to communicate threats and facilitate progress towards long-term remediation.

Highly motivated with the willingness to take ownership / responsibility for their work and the ability to work alone or as part of a team.

The Team

The Penetration Testing team forms part of Security Assessment group within Enterprise Cybersecurity (ECS). The goal of the Security Assessment group is to proactively identify and remediate vulnerabilities in Fidelity’s applications and infrastructure. We work very closely with all of the key Business Units to ensure that they remain secure while they deliver key projects to advance the firm.

Certifications : Category :

Information Technology

Fidelity’s hybrid working model blends the best of both onsite and offsite work experiences. Working onsite is important for our business strategy and our culture. We also value the benefits that working offsite offers associates. Most hybrid roles require associates to work onsite every other week (all business days, M-F) in a Fidelity office.

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and / or associating with individuals with certain Criminal Histories.

#J-18808-Ljbffr

Create a job alert for this search

Penetration Tester • Boston, MA, United States

Related jobs
Privacy and Cybersecurity Associate - Boston

Privacy and Cybersecurity Associate - Boston

Direct Counsel • Boston, MA, US
Full-time
Direct Counsel is seeking a Privacy & Cybersecurity Associate with 4-6 years of practical experience to join an esteemed practice group in Boston, Chicago, Los Angeles, New York, or Washington,...Show more
Last updated: 30+ days ago • Promoted
Senior Cyber Security Engineer

Senior Cyber Security Engineer

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Senior Cyber Security Engineer, Security Validation (Remote).Key Responsibilities Lead Red Team engagements to emulate real-world threat actors and validate enterprise ...Show more
Last updated: 30+ days ago • Promoted
Junior Cybersecurity Engineer

Junior Cybersecurity Engineer

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Junior Cybersecurity Engineer to support the NNSA in protecting the nation's nuclear security infrastructure. Key Responsibilities Deploy and integrate cybersecurity too...Show more
Last updated: 2 days ago • Promoted
AWS Security Engineer

AWS Security Engineer

VirtualVocations • Dorchester, Massachusetts, United States
Temporary
A company is looking for an AWS Cybersecurity Architect for a short-term contract.Key Responsibilities : Design and manage AWS organizational governance, including Service Control Policies and mul...Show more
Last updated: 7 days ago • Promoted
Cybersecurity Engineer

Cybersecurity Engineer

VirtualVocations • Dorchester, Massachusetts, United States
Full-time
A company is looking for a Cybersecurity Engineer.Key Responsibilities Develop, implement, and update security protocols Collaborate with IT and stakeholders to design secure system architecture...Show more
Last updated: 30+ days ago • Promoted
Data, Privacy & Cybersecurity Associate

Data, Privacy & Cybersecurity Associate

Mosaic Recruits • Boston, MA, US
Full-time
Data, Privacy & Cybersecurity Associate.Works with clients across multiple sectors including financial services and healthcare. Knowledge of GDPR, CCPA, CPRA, and other global frameworks.Cover l...Show more
Last updated: 6 days ago • Promoted
Penetration Tester

Penetration Tester

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Penetration Tester to support client engagements and offensive security initiatives.Key Responsibilities Validate and triage bug bounty submissions for clients, confirm...Show more
Last updated: 30+ days ago • Promoted
Cybersecurity C-SCRM Lead

Cybersecurity C-SCRM Lead

VirtualVocations • Dorchester, Massachusetts, United States
Full-time
A company is looking for a Cybersecurity IV&V and Supply Chain Security (C-SCRM) Lead.Key Responsibilities Serve as the lead technical advisor for Third-Party Cyber Risk Management (TPCRM) and In...Show more
Last updated: 5 days ago • Promoted
Cybersecurity Content Developer

Cybersecurity Content Developer

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a PNPE Course Content Developer (Contract).Key Responsibilities Develop complete instructional content for approximately 20 hours of on-demand training, including video s...Show more
Last updated: 2 days ago • Promoted
Remote Prisma Cloud Engineer

Remote Prisma Cloud Engineer

VirtualVocations • Lowell, Massachusetts, United States
Remote
Full-time
A company is looking for a Remote Prisma Cloud Engineer to join a leading cybersecurity organization.Key Responsibilities Understand customer requirements and security roadmap to implement approp...Show more
Last updated: 30+ days ago • Promoted
Senior DFIR Analyst

Senior DFIR Analyst

VirtualVocations • Dorchester, Massachusetts, United States
Full-time
A company is looking for a Sr Digital Forensics and Incident Response (DFIR) Analyst.Key Responsibilities Protect the organization's IT assets as part of the Cybersecurity Operations Center (CSOC...Show more
Last updated: 2 days ago • Promoted
Cyber Exercise Program Lead

Cyber Exercise Program Lead

State Street • Quincy, Massachusetts, United States
Full-time
This job is with State Street, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.Who we are ...Show more
Last updated: 24 days ago • Promoted
Cybersecurity Engineer (SOAR) [JOB ID 20250924]

Cybersecurity Engineer (SOAR) [JOB ID 20250924]

Phoenix Cyber • Boston, MA, US
Full-time
Phoenix Cyber is looking for Cybersecurity Engineers to join our client delivery team.This is a remote, work-from-home position with the possibility of minimal travel within the continent...Show more
Last updated: 30+ days ago • Promoted
Internal Penetration Tester

Internal Penetration Tester

VirtualVocations • Dorchester, Massachusetts, United States
Full-time
A company is looking for an Internal Penetration Tester to join a high-impact cybersecurity team in a fully remote role.Key Responsibilities Conduct internal penetration tests across Windows and ...Show more
Last updated: 13 days ago • Promoted
Penetration Testing Analyst

Penetration Testing Analyst

VirtualVocations • Dorchester, Massachusetts, United States
Full-time
A company is looking for a Security Analyst, Penetration Testing.Key Responsibilities Perform technical testing against various targets, including network and web application penetration testing ...Show more
Last updated: 30+ days ago • Promoted
Director of Cyber Third-Party Assurance

Director of Cyber Third-Party Assurance

MassMutual • Boston, MA, United States
Full-time
Full-Time, Boston, Springfield.As the Director of the Cyber Third-Party Assurance team you will work in a fast-paced, collaborative environment overseeing the onboarding and continuous monitoring o...Show more
Last updated: 24 days ago • Promoted
Cybersecurity Vulnerability Management Lead

Cybersecurity Vulnerability Management Lead

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Vulnerability Management Team Lead to oversee cybersecurity vulnerability management efforts.Key Responsibilities : Develop and lead the enterprise-wide product security...Show more
Last updated: 5 days ago • Promoted
Cybersecurity Subject Matter Expert

Cybersecurity Subject Matter Expert

VirtualVocations • Lowell, Massachusetts, United States
Full-time
A company is looking for a Cybersecurity Subject Matter Expert to support a DoD client.Key Responsibilities Provide expert support, research, and analysis of complex cybersecurity problems Condu...Show more
Last updated: 30+ days ago • Promoted